PT-2020-19879 · One Identity · One Identity Password Manager

Clément Cruchet

·

Published

2020-11-13

·

Updated

2021-07-21

·

CVE-2020-7962

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions One Identity Password Manager version 5.8
Description An issue was discovered in One Identity Password Manager where an attacker could enumerate valid answers for a user. This is possible because the HTTP response content returns 'WRONG ID' only when the answer is incorrect, allowing an attacker to detect a valid answer and reuse it later for a password reset on a chosen password.
Recommendations For One Identity Password Manager version 5.8, consider restricting access to the password reset functionality until a patch is available. As a temporary workaround, modify the HTTP response content to not disclose whether the answer is correct or not, preventing attackers from enumerating valid answers. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7962

Affected Products

One Identity Password Manager